CRITICAL 9.8 Microsoft

CVE-2023-20032

On Feb 15 2023 the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier 0.105.1 and earlier and 0.103.7 and earlier could allow an unauthenticated remote attacker to execute arbitrary code. This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process or else crash the process resulting in a denial of service (DoS) condition. For a description of this vulnerability see the ClamAV blog ["https://blog.clamav.net/"].

Microsoft Security Update 2023-Feb: On Feb 15 2023 the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier 0.105.1 and earlier and 0.103.7 and earlier could allow an unauthenticated remote attacker to execute arbitrary code. This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process or else crash the process resulting in a denial of service (DoS) condition. For a description of this vulnerability see the ClamAV blog ["https://blog.clamav.net/"].

Affected Products

References

Published: 2023-02-14 · Source: Microsoft · Feed updated: 2026-08-20
This critical severity vulnerability with a CVSS score of 9.8 was published on 2023-02-14 via Microsoft. EPSS score: 29.3% (top 2% of all CVEs by exploitation probability). Affected: cbl2 clamav 0.105.2-1 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2023-02-14 · 1283 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-62878Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternCRITICAL9.9
CVE-2021-20231A flaw was found in gnutls. A use after free issue in client sending key_share eCRITICAL9.8
CVE-2021-20232A flaw was found in gnutls. A use after free issue in client_send_params in lib/CRITICAL9.8
CVE-2022-48337GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacCRITICAL9.8
CVE-2025-0665eventfd double closeCRITICAL9.8
CVE-2025-68615Net-SNMP snmptrapd crashCRITICAL9.8
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.